Written from operating and development experience. Adapt the principles to the risk and scale of your own system.
01

Preserve the current state

Take file and database backups before changing themes, plugins, credentials or server configuration. Keep a record of the time, symptoms and recent changes. A backup is useful only when you know how it will be restored.

02

Find the actual failure

Check application logs, server logs, recent updates, user accounts, scheduled tasks and database changes. A visible error may be the result of a deeper security, resource or compatibility problem.

03

Repair in controlled steps

Change one layer at a time and verify the important business journeys after every major step: homepage, login, enquiry, checkout, email and mobile use. Avoid replacing half the system when one component is responsible.

04

Close the route back in

A clean page does not prove a clean website. Remove unauthorised access, rotate credentials, update vulnerable components, review permissions and confirm that malicious scheduled jobs or database entries are gone.

05

Leave a useful handover

The business team should know what failed, what was changed, what remains risky and what should happen next. Technical work creates more value when it reduces future uncertainty.

Have a related requirement?

Bring the context and we will help identify the useful next step.

Discuss your project